2012 CVE Vulnerabilities
5,939 CVEs published in 2012.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2012-6341 | MEDIUM | 6.5 | 1.3% | Feb 6, 2020 | An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a mali... |
| CVE-2012-6340 | MEDIUM | 4.6 | 1.2% | Feb 6, 2020 | An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial program... |
| CVE-2012-6309 | HIGH | 7.5 | 1.1% | Feb 6, 2020 | A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malici... |
| CVE-2012-6307 | HIGH | 8.8 | 5.6% | Feb 6, 2020 | A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious... |
| CVE-2012-6306 | CRITICAL | 9.8 | 1.3% | Feb 6, 2020 | A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file. |
| CVE-2012-6297 | HIGH | 8.8 | 1.7% | Feb 6, 2020 | Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containin... |
| CVE-2012-2593 | MEDIUM | 6.1 | 6.2% | Feb 6, 2020 | Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta... |
| CVE-2012-5686 | CRITICAL | 9.8 | 4.8% | Feb 4, 2020 | ZPanel 10.0.1 has insufficient entropy for its password reset process. |
| CVE-2012-5618 | CRITICAL | 9.8 | 1.2% | Feb 4, 2020 | Ushahidi before 2.6.1 has insufficient entropy for forgot-password tokens. |
| CVE-2012-6133 | MEDIUM | 6.1 | 1.5% | Jan 30, 2020 | Multiple cross-site scripting (XSS) vulnerabilities in Roundup before 1.4.20 allow remote attackers to inject arbitrary ... |
| CVE-2012-5776 | MEDIUM | 5.4 | 0.5% | Jan 29, 2020 | Dokeos 2.1.1 has multiple XSS issues involving "extra_" parameters in main/auth/profile.php. |
| CVE-2012-4383 | HIGH | 8.8 | 0.9% | Jan 29, 2020 | contao prior to 2.11.4 has a sql injection vulnerability |
| CVE-2012-6610 | HIGH | 8.8 | 10.9% | Jan 28, 2020 | Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitra... |
| CVE-2012-6609 | HIGH | 7.5 | 2.1% | Jan 28, 2020 | Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J... |
| CVE-2012-6114 | MEDIUM | 5.5 | 0.4% | Jan 28, 2020 | The git-changelog utility in git-extras 1.7.0 allows local users to overwrite arbitrary files via a symlink attack on (1... |
| CVE-2012-6448 | MEDIUM | 6.1 | 1.5% | Jan 27, 2020 | Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web scrip... |
| CVE-2012-1496 | HIGH | 8.8 | 2.5% | Jan 27, 2020 | Local file inclusion in WebCalendar before 1.2.5. |
| CVE-2012-1495 | CRITICAL | 9.8 | 79.8% | Jan 27, 2020 | install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user... |
| CVE-2012-6613 | HIGH | 7.2 | 2.0% | Jan 25, 2020 | D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admi... |
| CVE-2012-6494 | MEDIUM | 6.1 | 1.2% | Jan 25, 2020 | Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's... |
| CVE-2012-6345 | HIGH | 7.5 | 1.1% | Jan 25, 2020 | Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information. |
| CVE-2012-6344 | MEDIUM | 6.1 | 0.7% | Jan 25, 2020 | Novell ZENworks Configuration Management before 11.2.4 allows XSS. |
| CVE-2012-6451 | CRITICAL | 9.8 | 2.6% | Jan 24, 2020 | Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability |
| CVE-2012-6302 | HIGH | 7.8 | 0.3% | Jan 24, 2020 | Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox. |
| CVE-2012-6663 | HIGH | 7.5 | 9.5% | Jan 23, 2020 | General Electric D20ME devices are not properly configured and reveal plaintext passwords. |
Check if your code is affected by 2012 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now